Author Archives: Michael Froomkin

Obama Unveils “Consumer Privacy Bill of Rights”

Today the the Obama Administration is unveiling its new “Consumer Privacy Bill of Rights” (quoted in full at the end of this post) which they tout “as part of a comprehensive blueprint to protect individual privacy rights and give users more control over how their information is handled.” [Update: The White House issued this ‘white paper’, Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy that it says provides the background for the proposal. Despite the January cover date, I think it’s new, suggesting that there may have been some last-minute tussle about the contents?] [Update2: White House “Fact Sheet” on ‘Consumer Privacy Bill of Rights’.]

But as far as I can tell from my initial read, this is only a first step towards rules with a tooth or two. Next, our friends at NTIA (the people who gave you the modern ICANN), will be “conven[ing] Internet companies and consumer advocates to develop enforceable codes of conduct that comply with the Consumer Privacy Bill of Rights, building on strong enforcement by the Federal Trade Commission. The Administration will also work with Congress to enact comprehensive privacy legislation based on the rights outlined here.” Good luck with that in this Congress.

NTIA does have a strong and smart leader right now, Lawrence E. Strickling, the Assistant Secretary for Communications and Information, so this could be good. On the other hand, Strickling has shown willingness to carry the trademark lobby’s water on some ICANN issues (what else is new?), so this bears watching. On the good side, the administration is asking for enforceable legislation, not some blurry new public-private partnership. And the Commerce Department wrote a pretty good requirements document for what the policy should look like in its recent National Strategy for Trusted Identities in Cyberspace (April 2011). That document envisioned an “Identity Ecosystem” described as a system that will enhance privacy and civil liberties:

The Identity Ecosystem will use privacy-enhancing technology and policies to inhibit the ability of service providers to link an individual’s transactions, thus ensuring that no one service provider can gain a complete picture of an individual’s life in cyberspace. By default, only the minimum necessary information will be shared in a transaction. For example, the Identity Ecosystem will allow a consumer to provide her age during a transaction without also providing her birth date, name, address, or other identifying data.

In addition to privacy protections, the Identity Ecosystem will preserve online anonymity and pseudonymity, including anonymous browsing.

However, while setting out the outlines of how such a system might work in theory, the Strategy did not attempt to explain key aspects of how its ambitious goals might be attained in practice. Instead it sets out a ten-year roadmap, in which the first three to five years require “standardization of policy and technology” based on the twin pillars of underlying reliable offline credentials and private-sector leadership. Worse, only one month later, however, the White House released its International Strategy For Cyberspace, a document that while by no means all bad (it extolled the Internet’s benefits and opportunities), also warned darkly of the Internet’s dangers:

Extortion, fraud, identity theft, and child exploitation can threaten users’ confidence in online commerce, social networks and even their personal safety The theft of intellectual property threatens national competitiveness and the innovation that drives it These challenges transcend national borders; low costs of entry to cyberspace and the ability to establish an anonymous virtual presence can also lead to “safe havens” for criminals, with or without a state’s knowledge Cybersecurity threats can even endanger international peace and security more broadly, as traditional forms of conflict are extended into cyberspace.

And it is this latter document, not the better Identity Management paper from a month earlier, that gets cited in today’s press release about the “Consumer Privacy Bill of Rights”. Which vision will prevail – the primarily pro-privacy vision or the Internet-as-danger vision? The Administration’s press release sounds some positive notes, for example this one:

Achieving privacy policies for a Global, Open Internet: U.S. companies doing business on the global Internet depend on the free flow of information across borders. The Administration’s plan lays the groundwork for increasing interoperability between the U.S. data privacy framework and those of our trading partners.

At very hurried first glance the Consumer Privacy Bill of Rights idea seems based on principles that actually sound good…but may not be quite as great as they sound:

American Internet users should have the right to control personal information about themselves. Based on globally accepted privacy principles originally developed in the United States, the Consumer Privacy Bill of Rights is a comprehensive statement of the rights consumers should expect and the obligations to which companies handling personal data should commit. These rights include the right to control how personal data is used, the right to avoid having information collected in one context and then used for an unrelated purpose, the right to have information held securely, and the right to know who is accountable for the use or misuse of an individual’s personal data.

Does this mean the US will catch up with the EU’s data protection regime? I can’t tell for sure, but my first guess is “no”. To say that these are “obligations to which companies handling personal data should commit” is carefully not to say that these are obligations to which corporations will be required to adhere. At least not yet. Or at most only sectorally, rather than generally. Meanwhile, though, we’re going to kick the can down the road a bit, and “convene stakeholders including industry and privacy advocates to develop enforceable codes of conduct that implement the principles in the Consumer Privacy Bill of Rights for specific industry sectors.” But only those rules that “will keep up with, and not hamper, the pace of innovation.” So if your business model is, like Facebook or Google, based on using consumer information, then what?

There is one thing everyone agrees on – that companies should keep their promises about privacy and that the FTC can enforce on them when they do not – and this will remain a major enforcement tool. That’s good as afar as it goes, but in most cases that is only as far as your carefully drafted EULA.

The Administration seems to envision a legislative proposal, I would imagine after the election. It will set out the “basic principles the Administration believes should be reflected in a privacy law” which will on the one hand involve proposing “clear and actionable rights” while also providing “a way for companies to be confident that they are respecting these rights through an FTC-approved enforcement safe harbor.”

Let the food fight begin?

Here is the advance text of the Obama administration’s “Consumer Privacy Bill of Rights”:

Continue reading

Posted in Law: Privacy | Comments Off on Obama Unveils “Consumer Privacy Bill of Rights”

Bitcoin & Gresham’s Law & Botnets

Philipp Güring and Ian Grigg have e-published Bitcoin & Gresham’s Law – the economic inevitability of Collapse (PDF):

Abstract. The Bitcoin economy exhibits remarkable and predictable stability on the supply side based on the power costs of mining. However, that stability is challenged if cost-curve assumption is not solely expressed by the fair cost of power. As there is at least one major player, the botnets, that can operate at a power-cost-curve of zero, the result is a breach of Gresham’s Law: stolen electricity will drive out honest mining. This has unfortunate effects for the stability of the Bitcoin economy, and the result is inevitable collapse.

via Financial Cryptography.

Previously: Checking In With Bitcoin (10/25/11).

Posted in Cryptography, Econ & Money | 1 Comment

We Robot 2012 Is Going to Be Great

We Robot is taking shape: We’ve announced a diverse group of Speakers & Authors who combine to make up an exciting Program and today have opened up Registration.

Seating is limited, so registration will be required to attend. See you there!

Posted in Robots | Comments Off on We Robot 2012 Is Going to Be Great

Could This Be the Best Argument for Taking Drugs?

I don’t know exactly what the Great Grimmelmann’s “inner stoner” has been smoking, but I think we could all do with a hit of it.

Here are two cute ideas for law reform:

Stoner Law Reform: Fee-Shifting. I think it’s interesting. Because the marginal utility of money is not linear, I’m still not sure about it, but it’s still interesting.

Stoner Law Reform: Trial by DVD. I really like this one.

He promises more to come. (I hope he has a prescription for that stuff. It does seem to be what the doctor ordered.)

Posted in Law: Practice | 1 Comment

Obama Tix in High Demand

I would imagine that if you are only now thinking about getting in line to get an Obama ticket, your odds are lousy, as students began lining up last night:

Students began lining up around 6:30 p.m. Tuesday and by early Wednesday, police estimated there were around 850 in line hoping to get tickets to see Obama’s speech at UM’s BankUnited Center Fieldhouse Thursday.

Students brought lawn chairs, tents and air mattresses to make their wait more comfortable. Many spent their time watching movies, sleeping and even studying.

The university wouldn’t say how many tickets were available, at the request of the White House, but most students said just the chance to see Obama was worth the wait.

The tickets will be distributed at 8:30 a.m. Officials said students who were in line by 6:30 a.m.

Still nothing about faculty tickets. I suppose the students have more money. They certainly will make a more attractive backdrop on TV.

Previously: Obama Visit: No Faculty Wanted?.

Posted in 2012 Election, U.Miami | Comments Off on Obama Tix in High Demand

What He Said (Copyright Dept.)

Randy Picker has it exactly right in Politics, Copyright and the First-Amendment Commons.

When I saw NBC’s mendacious moaning about the Romney campaign’s use of archival NBC footage from 1997 of Tom Brokaw reporting on Newt Gingrich’s ethics problems, I immediately thought it to be about as fair use as fair use can be. But Picker also sees a bigger picture:

[T]he trump card that NBC and Brokaw sought to play would seem to mean that professional video representations of historical facts would simply be taken off of the table for political campaigns. It is hard to see how NBC and similar organizations could ever consent to use, given that consent itself would seem to be inconsistent with the neutral role of news organizations. Far better to have the fair use regime, where there is no consent and no sense of endorsement by a news organiation of one campaign over another.

Then we get to the bigger picture on this. I have this sense, with more frequency than I would like, that major media organizations think of the First Amendment as something that runs in their favor but never against them. A First Amendment for me but not for thee. It would have been nice if NBC and Mr. Brokaw had seen this as an opportunity to invest in the First Amendment ecosystem. That would have meant acknowledging the legitimacy of the use of the video clip by the Romney campaign and the need for such use in a vibrant democracy. Instead, NBC saw its interest in the narrowest terms possible and threw away a great opportunity to demonstrate how the First Amendment should work in a robust democracy.

(PS. For those with a poor memory of ancient history as regarding second-rate political figures, Newt Gingrich was briefly considered a serious challenger to Rick Santorum in the 2012 GOP Presidential contest.)

Posted in Law: Copyright and DMCA | Comments Off on What He Said (Copyright Dept.)